Fake ChatGPT Sites in Google Ads Are Installing RAT Malware on Business Computers
If your staff Google "ChatGPT" to find the tool rather than typing the URL, they are now an active target: attackers have built convincing fake ChatGPT chatbots, bought Google sponsored ad placements for them, and are using them to silently install remote access malware on Windows computers.
Security firm Huntress confirmed at least 40 infections in this campaign (published 29 September 2026). The attack works in three steps: click a sponsored ad, get shown a fake Cloudflare verification page, run the PowerShell command it tells you to paste. That command installs a RAT, giving attackers remote desktop control, audio and camera access, and the ability to drop further malware. A persistence mechanism disguised as "Canon Configuration Reader" survives reboots. OpenAI removed the initial malicious GPTs but variants remained active at time of publication.
ChatGPT is now a daily tool for staff across Sydney, Melbourne, Brisbane and regional NSW, and most people access it via Google search rather than a saved bookmark. That is the exact behaviour this campaign exploits. Three things to do today: brief your team that ChatGPT lives at chatgpt.com, typed directly into the browser; check your endpoint security covers PowerShell behavioural detection; and tell staff to report any unexpected PowerShell windows immediately.
Written by Dan Briggs, Senior IT Consultant, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across the Northern Beaches, wider Sydney, Central West NSW, Melbourne and Brisbane.
Frequently Asked Questions
Not sure if your team is protected against this kind of attack?
We can check your endpoint security coverage and run a quick security awareness briefing for your staff. It takes an hour and it's the most cost-effective thing you can do this week.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
